Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security audit identifies that several critical servers and workstations in the engineering department are running outdated operating systems with known vulnerabilities. The IT department cites application compatibility issues as a reason for not upgrading. Which endpoint security best practice is being neglected, and what is its primary purpose?

  1. AData Loss Prevention: To prevent sensitive information from leaving the organization.
  2. BRegular Patch Management: To fix known security vulnerabilities and bugs.
  3. CSecurity Awareness Training: To educate users about phishing and social engineering.
  4. DPrinciple of Least Privilege: To restrict user access to sensitive data.
Show answer & explanation

Correct answer: B. Regular Patch Management: To fix known security vulnerabilities and bugs.

Running outdated operating systems with known vulnerabilities directly violates the best practice of regular patch management, whose primary purpose is to apply security updates to fix these very vulnerabilities.

Why the other options are wrong

  • A. DLP prevents data exfiltration, which is unrelated to outdated operating systems.
  • C. Security Awareness Training educates users, but the issue is technical system maintenance.
  • D. Least Privilege is about access rights, not system updates.

Patch Management

The process of systematically applying software updates (patches) to operating systems and applications to fix bugs, improve performance, and, most importantly, address security vulnerabilities.

  • Crucial for reducing the attack surface.
  • Helps mitigate known exploits.
  • Requires regular scheduling and testing.

Memory trick: Patching is like giving your software its immunization shots.

More Endpoint Security questions